Open-source atomic malware analysis

Analyze another

2026-04-08_4d945286195e1ed239d22906c9fb004b_elex_wannacry

PE
Verdict: HOSTILE
Mal-ecule
KO₇(Er₃P₂As₇AlC₃IS)H₅(DbFOs₃Po₃Ds)Md₂(Bi₈)Th
Size 91.3 KB download
First seen 56 days ago
Analyzed 54 days ago

Well-known

hostile severity, 100% confident.
malware/trojan/elex Storm DDoS Active Setup loader

Objectives

suspicious severity, 94% confident.
evasion/self-delete COMSPEC CreateProcess self-delete
suspicious severity, 93% confident.
persistence/login/startup Active Setup StubPath persistence
suspicious severity, 94% confident.
persistence/system/service Persists DLL through Windows service
notable severity, 90% confident.
anti-static/obfuscation Unusual PE section alignment

Micro-behaviors

notable severity, 95% confident.
data/embedded Complete PE resource extraction with data access
notable severity, 66% confident.
fs/file Copy files (Windows API ANSI)
notable severity, 92% confident.
os/registry Registry open create and write APIs
notable severity, 95% confident.
os/service Windows service admin import cluster
notable severity, 98% confident.
process/inject CreateRemoteThread API reference

Metadata

notable severity, 92% confident.
binary Overlay exceeds one-third
notable severity, 100% confident.
unsigned Binary is not digitally signed
baseline severity, 95% confident.
dylib::advapi32 links ADVAPI32.dll (CloseServiceHandle, RegOpenKeyExA, RegQueryValueExA, StartServiceCtrlDispatcherA, RegCreateKeyA, ... +10 more)
baseline severity, 95% confident.
dylib::comdlg32 links comdlg32.dll (GetFileTitleA)
baseline severity, 95% confident.
dylib::kernel32 links KERNEL32.dll (lstrcatA, lstrcpyA, GetEnvironmentVariableA, GetShortPathNameA, GetModuleFileNameA, ... +28 more)
baseline severity, 95% confident.
dylib::mfc42 links MFC42.DLL (ORDINAL 924, ORDINAL 800, ORDINAL 941, ORDINAL 535, ORDINAL 537)
baseline severity, 95% confident.
dylib::msvcp60 links MSVCP60.dll (??0_Winit@std@@QAE@XZ, ??1_Winit@std@@QAE@XZ, ??1Init@ios_base@std@@QAE@XZ, ??0Init@ios_base@std@@QAE@XZ)
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)
baseline severity, 100% confident.
signed::unsigned Binary is not digitally signed

Third-party

notable severity, 90% confident.
SigBase/SUSP/Imphash Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)

20 of 56 traits shown

Identity

SHA-256 192f65e31b583b4b6851d8644fd70d58efc4c253be7e53dcff63e46d5a5dbea8
Filename 2026-04-08_4d945286195e1ed239d22906c9fb004b_elex_wannacry

Origin

Source harvest
Feed datasets
Ecosystem vxunderground-inthewild

Timeline

First seen 24 Apr 2026 16:17 UTC
Last analyzed 26 Apr 2026 22:24 UTC
Last updated 26 Apr 2026 22:24 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d